Dridex
Malware⚠️ Overview
Dridex is a sophisticated banking trojan and botnet first discovered in 2014 by researchers at IBM X-Force, attributed to the Russian cybercriminal group Evil Corp (also tracked as TA505 and INDRIK SPIDER). It functions primarily as a credential stealer and malware dropper, using a modular architecture to deliver second-stage payloads like ransomware and remote access tools. According to MITRE ATT&CK, Dridex is mapped to software S0384 and is categorized under the Banker and Botnet malware families.
🔧 Technical Capabilities
Dridex spreads via malicious spam campaigns using weaponized Microsoft Office documents (CVE-2017-0199 and CVE-2017-8759) that execute macros to download the main payload. Once installed, it performs man-in-the-browser attacks by injecting code into web sessions to steal banking credentials and redirect transactions. The botnet communicates over HTTP with encrypted command-and-control infrastructure, using a custom protocol that employs RSA and AES encryption for data exfiltration. Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include sandbox detection, process hollowing into legitimate Windows processes like svchost.exe, and disabling security software via DLL sideloading. Dridex also leverages PowerShell (T1059.001) for script-based execution and employs domain generation algorithms (DGA) for resilient C2 communication.
📜 History & Notable Incidents
First surfacing in 2014, Dridex initially targeted UK banks, causing an estimated £20 million in losses by 2015. Major campaigns included the 2018 deployment of the BitPaymer ransomware and the 2020 WastedLocker ransomware, both linked to Evil Corp. Notable law enforcement actions include the 2015 FBI/Europol takedown that seized over 30 command-and-control servers, and the 2019 US Department of Justice indictment of Evil Corp members Maksim Yakubets and Igor Turashev. Dridex exploited several CVEs, including CVE-2018-4878 (Adobe Flash), CVE-2018-20250 (WinRAR), and CVE-2018-8174 (VBScript Engine).
🔍 Detection Indicators
Known file hashes vary per campaign, but researchers from CrowdStrike and FireEye have published mutex names such as GlobalDREX_<random> and registry keys under HKCUSoftwareClassesCLSID used for persistence. Network indicators include HTTP requests to domains generated by DGA patterns (e.g., using a seed like dridex) and User-Agent strings such as Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1). Behavioral signatures include unexpected macro execution in Office documents, process injection into explorer.exe, and repeated connections to IPs on non-standard ports (e.g., 443, 80, 8080).
☠️ Risk & Impact
Dridex has caused significant financial damage, with losses exceeding $100 million globally through credential theft, wire transfer fraud, and ransomware deployment. The malware disproportionately affects the banking, healthcare, and government sectors, as detailed in reports from the UK National Cyber Security Centre and the US CISA. In 2019, the FBI attributed over 345,000 infections in the United States alone, with victims ranging from small businesses to Fortune 500 companies.
🛡️ Mitigation
Recommended defenses include disabling Office macros by default (applying Group Policy to block macros from the internet), patching vulnerabilities exploited by Dridex (CVE-2017-0199, CVE-2018-4878), and deploying endpoint detection and response tools that monitor for process injection and abnormal HTTP traffic. Organizations should also implement threat intelligence feeds to block known C2 domains, enforce application whitelisting, and conduct regular phishing awareness training for employees.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.